PT-2023-6527 · Mozilla+5 · Firefox+5

Shaheen Fazim

·

Publicado

2023-10-24

·

Atualizado

2025-03-14

·

CVE-2023-5729

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 119
Description A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt, potentially obscuring the fullscreen notification and allowing for spoofing attacks. The vulnerability is related to errors in the representation of information in the user interface. It could be leveraged by a remote attacker to conduct spoofing attacks.
Recommendations For versions prior to 119, update to Firefox version 119 or later to resolve the issue. As a temporary workaround, consider disabling WebAuthn prompts when entering fullscreen mode to minimize the risk of exploitation. Restrict access to fullscreen mode for untrusted websites to reduce the attack surface.

Correção

UI Misrepresentation of Critical Information

Clickjacking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-6639
ALT-PU-2024-13898
ALT-PU-2024-15839
ALT-PU-2024-15840
BDU:2023-07274
CVE-2023-5729
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2023_4214-1
OPENSUSE-SU-2024:13385-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2023:4212-1
SUSE-SU-2023:4213-1
SUSE-SU-2023:4214-1
USN-6456-1
USN-6456-2

Produtos afetados

Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu